Azuracast

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    2
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-76836

    AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass

    Last Modified: Aug 24, 2026
    Published: Aug 24, 2026

    CVE-2026-67917

    zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validation or sanitization. This allows a remote attacker to escalate privileges

    Last Modified: Aug 18, 2026
    Published: Aug 17, 2026

    CVE-2026-42605

    AzuraCast: Path Traversal in `currentDirectory` Parameter Enables Remote Code Execution via Media Upload

    Last Modified: May 14, 2026
    Published: May 09, 2026

    CVE-2026-42606

    AzuraCast: Password Reset Poisoning via Untrusted X-Forwarded-Host Header Leads to Account Takeover and 2FA Bypass

    Last Modified: May 14, 2026
    Published: May 09, 2026

    CVE-2025-67737

    AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE

    Last Modified: Feb 17, 2026
    Published: Dec 12, 2025
    Items Per Page
    Azuracast Vulnerabilities & Security CVEs | CVE-DB